logo

NDAA puts AI cyber risk in the crosshairs

ID: 1e3fa750-368e-58bc-baf0-4348fd7c6704

STIX ID: report--1e3fa750-368e-58bc-baf0-4348fd7c6704

Feed Name: ReversingLabs Blog

Date Published: 2025-12-11

Date Updated: 2026-04-29

Author: Saša Zdjelar

...
...

This article analyzes the U.S. National Defense Authorization Act’s new focus on AI security, highlighting Section 1512’s extension of SBOM requirements to AI systems and Section 1513’s call for cybersecurity and governance policies addressing model tampering, adversarial attacks, and AI supply chain risks. It cites examples such as compromised Hugging Face tokens, the Shai-hulud npm worm, and malicious models like nullifAI to illustrate the growing threat landscape, and advocates a proactive shields up posture. The piece also promotes visibility and scanning capabilities for AI/ML models (e.g., PKL, ONNX) and ML-BOMs, emphasizing that while no silver bullet exists, transparency and supply chain controls are becoming essential.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.